Developer Toolbox

text/plain

text/plain is text with no markup to interpret. It is the simplest text type, and the one to use for logs, notes and anything else meant to be shown exactly as written.

Open in cURL Builder A request with this type is filled in.

Header

Content-Type: text/plain; charset=utf-8

At a glance

Extensions
.txt
Kind
Text
Parameters
charset. Without it the default is US-ASCII (RFC 2046), so always send charset=utf-8.
In a browser
Shows the text as is, in a monospace font.

With curl

curl https://api.example.com/notes \
  -H 'Content-Type: text/plain; charset=utf-8' \
  --data-binary 'Hello, world'

With fetch

// A string body without a header goes out as text/plain;charset=UTF-8.
await fetch('https://api.example.com/notes', { method: 'POST', body: 'Hello, world' });

Common mistakes

  • Missing charset

    Without charset, a client may read UTF-8 as Latin-1 and show é for é. Always send charset=utf-8.

  • A simple CORS request

    A POST with text/plain needs no CORS preflight, so a page on another site can send one to your API; the user's cookies go with it unless they are SameSite=Lax or Strict. Do not rely on the content type to stop cross-site requests that change data.

  • nosniff keeps text as text

    Browsers used to guess HTML from text that looked like it. X-Content-Type-Options: nosniff stops that, and with it a script served as text/plain is refused too.